CVE-2025-4355: D-Link Dap-1520 Firmware
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
A vulnerability was found in Tenda DAP-1520 1.10B04_BETA02. It has been classified as critical. This affects the function set_ws_action of the file /dws/api/. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected products
- D-Link Dap-1520 Firmware: version 1.10b04 only
Published 2025-05-06. Last modified 2026-06-17.